|
256481
|
7.5 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
|
CWE-20
Improper Input Validation
|
CVE-2017-1000018
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256482
|
8.8 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-1000017
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256483
|
7.5 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.
|
CWE-20
Improper Input Validation
|
CVE-2017-1000016
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256484
|
6.1 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000015
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256485
|
7.5 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality
|
CWE-20
Improper Input Validation
|
CVE-2017-1000014
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256486
|
6.1 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
|
CWE-601
Open Redirect
|
CVE-2017-1000013
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256487
|
6.1 |
MEDIUM
Network
|
mysqldumper
|
mysqldumper
|
MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000012
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256488
|
6.1 |
MEDIUM
Network
|
mywebsql
|
mywebsql
|
MyWebSQL version 3.6 is vulnerable to stored XSS in the database manager component resulting in account takeover or stealing of information
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000011
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256489
|
7.8 |
HIGH
Local
|
audacityteam
|
audacity
|
Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-1000010
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256490
|
9.8 |
CRITICAL
Network
|
akeneo
|
product_information_management
|
Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.
|
CWE-78
OS Command
|
CVE-2017-1000009
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|